RULINGS.txt inventory for the spec audit
Source read in full: OSL-AUDITS/RULINGS.txt (2,977 lines). This is an inventory, not a BUILT or PROVEN assessment.
Count and ID scheme
- The file contains 75 distinct D-series ruling IDs, exactly matching the stated “75 owner rulings”: 66 base IDs (
D1–D50,D53–D68; there are no D51 or D52) plus nine addenda/corrections (D17a,D18a,D21a,D33a,D45(a),D45(b),D45(c),D54(a),D64(a)). - Before the D-series it also contains five unnumbered machine-checkable rulings; owner decisions 1–20 and corrections; global self-healing/sidebar/fidelity rulings; S1–S7; Q1–Q7; T1–T7 (in non-contiguous groups); R1–R4; and several named owner rulings. Those are inventoried separately below because they still outrank design, plan, and code.
- A D-series ID is often a package of several independently testable capabilities. Do not mistake “75 IDs” for only 75 assertions.
Earlier rulings and decisions still relevant to product capability
Five opening machine-checkable rulings
| Ruling | Requirement | Status/conflict |
|---|---|---|
voice ships ABSENT, not greyed | If voice has no client, omit voice controls; never show disabled controls that imply a feature exists. | Superseded for V1 by “nothing left unbuilt”: voice now ships, so absence proofs retire. Honesty principle remains. |
shipped default is Direct | Ship Direct routing by default; flip to Tor only after rerunning the packaged-build default-answer send proof (task 4900). | Conditional; file does not itself say the proof later passed. |
beacons and custom roles are CUT | Record beacons/custom roles as cut gaps rather than build them in the 48-hour release. | Superseded by “nothing left unbuilt,” D2, D16 and enclave self-moderation: beacons and custom roles ship. |
X, Instagram and Messenger ship only if their proofs pass | Catalogue presence is allowed, but sending/Ready status is gated per carrier by that carrier’s own proof. | Still binding; D20 explicitly says X’s design is bound but does not promote X into shipping scope. |
cut feature recorded in gap list | Never delete a specification when deferring/cutting it; record it and the ruling in the gap list. | Standing honesty/traceability rule. |
Decisions 1–20 (9 August) and corrections
| ID | Concise requirement | Status/conflict |
|---|---|---|
1 | Pin three Discord burner accounts to three machines; do not ask owner to sign in yet or block other work. | Later test topology changed; account readiness is governed by D59/D63. |
2 | One signing key, held only by Liam. | Standing; interacts with compromised-key recovery S3. |
3 | Signal uses screen reading, detects breakage, self-repairs, and visibly refuses if repair is impossible; linked-device route rejected. | Expanded product-wide by universal self-healing. |
4 | Safety number is 60 digits grouped by five plus scannable QR. | Reaffirmed D12(d); design’s 12 digits are placeholder/void. |
5 | “Messages waiting” shows the count first and messages on open; look-back equals relay retention. | Standing. |
6 | Metering uses anonymous/unlinkable vouchers, never a per-account ledger. | Refined by purchase ruling and late voucher correction: honest small-anonymity-set limit. |
7 | Relay capacity must make Pro’s 30-day retention real. | Standing. |
8 | No refunds. A $5 purchasable top-up buys extra data; 180-day purge and downgraded-file lifetime must be specified. | Pack ladder later set by D57; no-refund remains. |
9 | Team measures performance ceilings and proposes them; owner ratifies. | Ultimately resolved by D44; D21 numbers were withdrawn by D21a. |
10 | Team chooses cover-format defaults. | D33 chooses word-choice-only default. |
11 | Public names use [A-Za-z0-9_], maximum 16, minimum 1. | Conflict: D47’s design says lowercase, max 30, min 3. Rulings outrank design, but D47 records owner-delivered behavior without explicitly superseding decision 11. Needs explicit reconciliation. |
12 | Hidden switches: owner asked which UI they belong to; no decision yet. | Open/ambiguous, not a shipping requirement by itself. |
13 | Two devices ship this release; multi-device sync is in scope. | Standing. |
14 initial | Mullvad moved to Settings; Tor stayed onboarding; forward secrecy pending. | Corrected: forward secrecy moved to Settings. D9 later shrinks Mullvad to one optional autoconnect setting. |
14 corrected | Forward secrecy/old-message behavior is a Settings capability, default “old messages stay locked forever”; remove its onboarding screen. | D43 later explicitly accepts screen 014 Old-message defaults despite D12(g); standalone-screen shape is therefore reopened/overridden. |
15 | Match full Appearance surface: accent/background swatches, hex entry, colour picker, avatar upload/colour, profile backgrounds, live preview. | Standing; design controls define exact surface. |
16 | No outside encryption review yet. | Reaffirmed T5: never claim one. |
17 | Team decides blocked wake-up connection behavior. | Delegation only; no concrete outcome in this file. |
18 | Cover tick is Pro-only. | Standing. |
19 | Tor and OSL LAN are mutually exclusive; explain why visibly at the point of choice. | Standing. |
20 initial | Eleven “small defaults” awaited a list. | Later 20(a) corrected, 20(b)–(h) accepted, 20(i) accepted with reservation; the actual eleven are not reproduced here, so this file alone is incomplete. |
20(a) | Onboarding’s chosen send trigger applies to every carrier, Telegram included. Cover text must never contain newline/CR/empty text because Enter commits it. | Standing. |
20(b)–(h) | Accepted “as written.” | Ambiguous here: exact requirements are absent from RULINGS.txt; must resolve through cited plan/source. |
20(i) | Accepted with reservation (“i guess?”); revisit if annoying. | Ambiguous here: exact requirement absent. |
20(j) | Exact ceilings delegated to team judgement. | Superseded by measured/approved D44 numbers. |
20(k) | Mail-reading cleanup accepted. | D30(b) later gives exact keep/delete split. |
20(l) | Sidebar retirement accepted and widened: remove rail everywhere and retire Inbox, People, Privacy, Activity, Connections; rehome honest content into bell/Settings. | Reaffirmed D12(a), D41. |
20(m) initial | Skip/gap-list “Accounts friends can see.” | Superseded same day: build full friends surface. |
20(m) corrected | Build OSL friends and Chats contacts as separate lists, who may add you, friend requests, and accounts friends can see. | Standing; Settings design is authority. |
Cross-product and named owner rulings before D1
| ID/name | Concise requirement | Status/conflict |
|---|---|---|
universal self-healing | Every screen-driven carrier adapter (Discord, Telegram, Signal, WhatsApp, X, Instagram, Messenger) detects UI/accessibility movement, repairs itself, and visibly refuses instead of guessing when repair fails. | D carrier-fidelity ruling extends this from behavior to appearance. |
sidebar removed entirely | No global sidebar/rail on any route; retire five routes and rehome their content or record a gap. | Reaffirmed D12(a)/D41; design pages drawing rail lose to ruling. |
carrier visual fidelity | Composer/eye overlays must exactly match live carrier UI; prove with real-account reference screenshots and structural visual diff; reject blank captures by distinct-colour count; continuously detect/restyle/refuse when carrier appearance changes. | Standing. Function-only results do not prove this. |
S1 | Windows-only V1. macOS/mobile deferred; Linux is build/screenshot harness, not product. | Standing. |
S2 | Build malware scanning and quarantine contract for protected downloads. | Standing planned capability. |
S3 | Build compromised root/update/signing-key recovery, including rotating a compromised root/offline verification key. | Standing. |
S4 | State and implement carrier-version support/repair-time policy when compatibility breaks. | Standing. |
S5 initial | No central reports, spam throttling, evidence collection, moderation tooling, or server content visibility; client blocking only. | Refined by enclave self-moderation and D14: enclave-local governance/local filtering allowed; OSL-central moderation still forbidden. |
S6 initial | Co-owner compromise/dispute question awaiting owner. | Resolved later by S6 resolved. |
S6 resolved | Co-owners may remove owners, delete enclave, lock others out; no dispute/appeal/adversarial defense. Warn plainly when granting co-owner that they can remove you/destroy enclave. | Standing. |
S7 | Fiat path deferred and Stripe disabled. | Superseded by in-app purchase ruling: Stripe/BTC/XMR ship. |
test resources | Calibration VPSs are off-limits. Azure disabled/read-only. Prefer free local resources and justify second-machine need. | “No VM” was superseded; D13 establishes local Hyper-V guest. |
UI-plan merge | Merge UI work into one plan but batch owner looks; mechanically check everything possible; rejected items become tasks; UI behavior is authoritative as well as appearance; every control/state needs a behavioral contract, execution proof, red proof, and explicit dead-control reporting. | Standing process/proof requirement. |
in-app purchases | Stripe, BTC and XMR buy vouchers/top-up in app. Purchase and redemption must be unlinkable; OSL stores no payment data; disclose card identity exposure, BTC public ledger, XMR privacy, confirmation waits, and failed/under/overpayment outcomes. | Supersedes S7; prices later D57. |
one plan + blind loop | Merge rewritten plan, UI, and purchases; blind agent reads only plan and reconstructs product; revise with fresh blind reviewer until all shipped scope is present, deferred scope absent, no ruling contradicted, no known silence. Only then execute. | Process requirement. |
mandatory final pass | After blind pass, perform unconditional whole-plan pass; retain small tasks, engine/tier, parent+red proof, starvation; research plan ordering/execution/integration as a system. | Process requirement. |
new plan picks up here | Reconcile actual state/ticks, build one compiling trunk, then build gaps; rerun interrupted tasks from scratch; do not trust ticks or discard genuine work. | Process requirement; later integration rulings update facts. |
vouchers correction | Build blind-token scheme despite small anonymity set; disclose timing/cohort correlation; say unlinked, not anonymous, at low volume. | Standing. |
VM correction | Prefer local Hyper-V or Sandbox, then Azure only if necessary; calibration VPS remains forbidden. | Supersedes “no VM”; D13 gives exact guest. |
Q1 | Recovery kit authorizes replacement and revokes all prior devices. Recover identity/name/friends/receive ability, not message history; show key change. If devices and kit both lost, account unrecoverable and name permanently tombstoned; warn on kit issuance. | Standing. |
Q2 | Ordinary offline send refuses immediately; no silent outbox/background retry. Crash retry after committed send unaffected. | Standing. |
Q3 | Disconnect locally deletes credentials/tokens, mapping, cached geometry/appearance, and cover-history pointers. Relink is fresh. Explain that already-sent carrier messages remain and disconnect is not deletion. | Standing. |
Q4/Q5 | Free 7-day, Pro 30-day, downgraded files 7-day retention. Export must be portable/decryptable/documented with attachments. Derive profitable pricing from measured storage/egress worst case. | Export is strengthened by T2; pricing later D57. |
Q6 | Launch is single-region, best-effort, daily ciphertext/key-record backups, documented restore tested once; no enterprise SLO. | T7 says independent disaster isolation deferred. |
Q7 | English-only launch, but externalize all user-facing strings; no translations/RTL/plural rules yet. | Standing. |
T1 | OSL may briefly use clipboard only with measured bounded window, crash-proof restore, history exclusion, and prior disclosure. | Superseded by D31, then scoped by D49/D54: user-consensual copy allowed; hidden clipboard workspace banned. |
T2 | Personal export must round-trip into clean local OSL as a functioning account, carrying identity/keys/friends/conversations/content/attachments/settings/memberships/device/recovery material. Name deliberate exclusions; prove actual export/import, not checksum. | Standing. |
T5 | No external encryption review this release; remove all wording implying independent review/audit/verification. | Standing. |
T4 | Enclaves have no hard member cap. Measure rekey threshold N; above it warn/show progress; removal must complete and removed member must lose future read access before success is reported. | Distinct from 20-person group chat under R1. |
T6 | Retention/cleanup works unattended with automatic retry/self-healing; alert owner via Telegram only when unrecoverable; promise no staffed response time. | Standing. |
T7 | Independent backups deferred; do not claim disaster isolation; state actual loss boundary and preserve deferred task. | Standing. |
T3 | All destructive confirmations use real operation counts, identify everyone affected, state what survives, and put “cannot be undone” last. Exact approved copy exists for burn conversation, burn enclave, remove device, stop account, and Scrub deletion. Gate fails if displayed count differs from destroyed count. | Standing. |
R1 | Group chat cap is 20. Enclaves have no cap and disclose/progress slow removal above measured threshold. | Standing. |
R2 | Cut all open native OSL Mail product work; completed work stays; external mail carriers unaffected. | Refined/superseded by D9(d): OSL Mail is post-V1/deferred, not deleted or superseded; V1 gates must not depend on it. |
R3 | Settings ships a per-carrier desktop-versus-web choice. | Standing. |
R4 | Username change locks further changes for 30 days; Settings ships private-account control. | Standing. |
nothing left unbuilt | Profiles/posts/stories, voice, beacons/custom roles all ship; lift holds; Azure fleet resource file stays superseded. Custom roles are access control, not central moderation. | Supersedes opening voice/beacon cuts. D16 reinforces no feature cuts. |
enclave self-moderation | Enclave-local roles, permissions, removal, mute, channel restriction, invite/post restriction, and signed in-enclave message deletion ship. No OSL reports/bans/sanctions/evidence/review/appeals/server visibility/global reputation. | Refines S5; D14 narrows AutoMod to local filtering. |
The 75 D-series owner rulings
| ID | Exact concise capability/requirement | Supersession, conflict, or ambiguity |
|---|---|---|
D1 | Remove decoy workspace. Stealth is normal OSL with no pre-existing protected/plaintext content visible; supersede decoy tasks. | Standing. |
D2 | Enclave roles are fully customizable; Steward, Builder, Everyone are defaults only. | Supersedes prior fixed rosters. |
D3 | Build bot framework: add/authenticate bots, scope visibility/actions, and treat read access as explicit enclave-key sharing. | D14 says existing 6824–6831 design stands; fill only named gaps. |
D4 | Redo onboarding to design: single Set up your apps surface; deleted pages absent. | D39 later restores separate Onboarding Detected page; install/detected history partially superseded. |
D5 | Onboarding app status is binary Detected/Not detected; account claiming belongs in Settings. | Standing. |
D6 | “Plaintext attachment” means typed text behaving as an encrypted attachment, including view-once/timer. It is never unencrypted. | Naming remains risky/ambiguous; rename recommended but not owner-ruled. |
D7 | Whitelist row toggles silently and reversibly, clearly showing new state; send no notification and show no confirmation dialog. | Standing. |
D8 | Story viewer chooses named (default), anonymous literal “user,” or hidden/no-count mode before opening. Apply at open, not retroactively; relay learns no viewer identity; disclose small-audience inference. | Supersedes zero-viewer-identity task clauses. |
D9 | No decoy/tutorial carousel. Preserve teaching of Lock/Eye/cyan ring elsewhere. Mullvad is at most one Settings autoconnect control and must be removed if true connection automation is impossible. OSL Mail is post-V1, preserved but not a V1 gate. | Refines R2 and decision 14. |
D10 | Final UI directory is authority for every shipping screen; deleted/non-screen pages do not ship; state variants remain one screen; synthetic controls do not ship while “needs app capability” does; follow stated build order. | Page count/details updated by D39/D50/D55. |
D11 | Eye is click toggle: click reveals exact words; second click hides. “Hold to peek” design/copy is void. | Explicitly overrides design. No auto-hide mitigation may be invented. |
D12 | Remove rail and five retired routes; ship enclave slow mode and AutoMod; password floor 12 plus strength score 3; safety number 60 digits+QR; send modes exactly single Enter/double Enter/Clipboard; WhatsApp byte budget; nine-step Strip coach with click-to-reveal; no Home feed; Old Messages in Settings. | Old Messages standalone later accepted D43. AutoMod narrowed D14. Sidebar standing. |
D13 | Use local Hyper-V guest OSL-QA-1 only for genuinely separate Windows install; local multi-instance identities first; Azure remains dead. | Supersedes no-VM ruling. |
D14 | AutoMod is client-side, post-decryption, enclave-scoped filtering only: no relay inspection/report/evidence/appeal/reputation/central record, no delete for others. Existing bot key-sharing/permissions model stays. Update disclosures honestly. | Reconciles S5 with later AutoMod request. |
D15 | Disappearing-message timer minimum one minute; no seconds. Maximum remains 30 days. | Minimum owner-confirmed; 30-day upper bound delegated/overturnable and conflicts with design’s 24h range. |
D16 | Cut nothing: forum channels, RSVP events, and stage voice all ship. Measure stage audience; cap/refuse visibly at measured limit rather than degrade. | Standing. |
D17 | Relay sees globally unique public name and nothing else. Encrypt display name, picture, status, bio, per-enclave presentation. Disclose this split and prove relay observer recovers public name but zero other fields. | Delegated/overturnable. Public-name format still conflicts between decision 11 and D47. |
D17a | Disclose profile ciphertext size/timing leakage. Encrypt profile material per scope to prevent byte-identical cross-enclave correlation. | Standing amendment to D17. |
D18 | New-joiner history may be re-shared by a member, never via old-key retention. Default off; forward-only from signed epoch; sharer named/visible; always zero pre-join keys; refuse feature if it cannot meet this design. | Standing. |
D18a | No history selection UI/election. When enabled, eligible history is the entire post-epoch window; any online member holding it may serve it. | Clarifies D18’s withdrawn word “selected.” |
D19 | Integration is plan work. Rebase rather than merge; every integration gates on app Rust build and tsc --noEmit; execute wiring tests rather than source grep; nothing is proven until present in one compiling/typechecking tree. | Standing proof rule; D32/D34 record later state. |
D20 | Timer destroys decryption on both devices for every carrier, including email/X design. Email pointer payload is destroyed while ordinary envelope remains. Do not claim control over patched clients/screenshots. X is not thereby promoted into release. | Standing. |
D21 | Original interactive/Scrub performance ceilings. | Entirely void under D21a; cite D44 instead. |
D21a | Withdraw D21 numbers because they contradicted real Windows baseline; do not choose unmeasurable send numbers before send path exists; decisions alone cannot pass gates. | D44 later supplies approved numbers, with provisional labels where unmeasured. |
D22 | Timer modes: key-only default; optional key+carrier-message where adapter truly supports deletion. Capability derived from live adapter. Deletion is best-effort; key destruction always happens; tell person on delete failure. Email has key-only. | Standing. |
D23 | Local data is permanent/unmetered and app remains usable at zero allowance; only relay handover waits. Never hide/lock local data when voucher expires. | Open question about already parked relay data later answered D40: delete at relay expiry. |
D24 | Low Data Mode parks nothing on relay; only moved meter changes. Require simultaneous recipient availability, local resendable wait, no silent parking fallback, unchanged encryption/cover, and explain privacy/convenience tradeoff. | Standing. |
D25 | Ship exact single-catalogue email timer sentence supplied in ruling; no paraphrase or omitted clause. Prove real protected email before/after timer and no X timer controls. | Exact copy is in RULINGS.txt and should be quoted from there in deliverable. |
D26 | Machine-grade every screen 1:1 against named design page before owner review. Compare control/text/route structure before pixels; missing reference fails; ignore synthetic demo data. | D65 exempts five owner-approved undesigned routes from parity, not behavior. |
D27 | Iterate screenshots until <1% pixel difference plus structural pass, same viewport/DPR and demo-data neutralization; red proof catches blank/downscaled/cropped cheating. | D45(c) later makes structural verdict authoritative where synthetic content/additions prevent whole-frame pixel identity. |
D28 | Never invent price/rate/ladder. Missing owner/ratified value must cause named refusal. | D57 later ratifies exact ladder. |
D29 | Canonical branch is local integration/full; reconcile origin-only commits deliberately; do not force-push until reconciled; typecheck canonical, not wrong lineage. | Historical reconciliation later completed D32. |
D30 | Beacon subscription without joining allowed. Delete unused/test-only mail readers but keep/document live rules by caller. Do not decide carrier mangling until real readback exists. | Standing. |
D31 | Original absolute clipboard ban; insert mail covers directly into hosted composer, never typing/paste/fallback. Packaged build must show zero hidden clipboard activity. | Scoped/superseded by D49 then D54: deliberate user-chosen clipboard action allowed; autonomous clipboard workspace remains banned. |
D32 | Integrated tree compiles Rust but had 32 TS errors. Before deleting unused symbol, compare branches; later D34 adds requirement to inspect downstream callees too. | State finding, not proof product works. |
D33 | Default cover carries bits in word choice only; capitalization/spelling off unless per-carrier readback passes. Safe ASCII/no links/emoji/markdown. Residual corruption handled by error correction, readback, self-heal/refusal. | Standing. |
D33a | No carrier transform is known to defeat actual word-choice ASCII output; “unpreventable” requires measurement against actual output. Measure Discord readback and narrow alphabet if needed. | Clarifies D33; still unmeasured, not proven. |
D34 | Restore missing offline wiring and TS fields. Never delete an unused function without checking what live machinery it alone calls. Hardcoded test statistics are invalid. Tuta Rust removal debt remains. | State/engineering guard, not end-to-end proof. |
D35 | Remove GMX fully from plan and code; do not damage shared mail plumbing. | D36 broadens removal to mail.com too. |
D36 | Remove mail.com too; preserve shared IMAP for Yahoo/AOL/iCloud. Supported mail carriers: Gmail, Outlook, Proton, Yahoo, AOL, iCloud. | Supersedes D35’s “preserve mail.com” constraint. |
D37 | Wordbank cover need not fool humans; it must not be recognized by machine classifier above 50% on balanced data. AI-cover human-naturalness bar remains. Existing near-100% detector result fails. | Standing; AI Windows feature absence D66. |
D38 | Owner’s already signed-in personal accounts may be test identities, but message only owner-controlled identities, never public post/CAPTCHA/2FA/password entry; evidence names personal account and real-message deletion risk. | Standing. |
D39 | Onboarding Detected is a shipping design page and app route; derive page counts dynamically. | Partly supersedes D10/D4. Authority was 71 here, later 72 under D50/D55. |
D40 | Relay storage clock starts at send and deletes uncollected object at expiry. View clock starts only on recipient open and gives full window. Prove independently; never share one timer. | Answers D23 parked-object question. |
D41 | EDITS.md is coequal authority with design pages. Old global sidebar still in code must be removed before more owner reviews. | Standing. |
D42 | Review rulings: no preselected choice; remove specified switch and justify three modes; defer AutoScrub screen; Scrub warning generic/universal; keep action placement/ratios and page B10 exact; rewrite owner questions in plain English. | Some labels A/B require mapping from review artifact; not self-contained in RULINGS.txt. |
D43 | Record 43-screen verdicts. Structural: delete recovery-word check and visibility pages; combine identity pages; Pro Code morphs to accepted state; rebuild Pro active; window controls ship; settings/Chats/Strip parity required. Prove animation with synchronized motion captures. Owner reviews one side-by-side moving page. | 003 handling superseded D48; 006/007 refined D47/D53; accepted-screen statuses superseded by later reviews. Old Messages screen accepted, overriding D12(g). |
D44 | Approved limits: 8GB target; 750MiB WS; 2s cold start; <1% idle CPU; 100ms typical/250ms worst keypress provisional; <=10% 8h growth provisional; 5GB disk provisional; 100k Scrub <=30m provisional. Provisional must be labeled/measured before V1. Relay deletes at expiry. Certain second identities deferred; owner review required for pack/ship decisions. | Supersedes D21/D21a numbers. D45/D57 later settle ship rule/ladder. |
D45 | Exclude discord-qa-shell from release/default features. Paid ladder must be data-only with no visible daily message cap; research operation cost before pricing. Free tier remains. Require measured multi-frame screenshot parity before owner review. | Ladder later ratified D57. |
D45(a) | Settings is one multi-section design page; compare app sections to page regions rather than assume separate files. | Corrected by D45(b): rendered page had eight sections and Window & Sounds was genuinely absent at that time. |
D45(b) | Correct authority mappings: Send Checks/Send Mode/Settings regions/OSLChats modal. Render design to establish sections. Four routes lacked references then; Security existed in design but app missed it. | Window & Sounds later added and ships D57. 003 deleted D48/D55. |
D45(c) | Synthetic demo accounts/content are not parity targets. Structural boxes/positions/computed typography decide verdict; pixel score only ranks. Exclude only explicitly ruled additions and report excluded pixels. | Refines D27’s raw <1% rule. |
D46 | Second review verdicts. Accepted screens freeze. Fix named defects only on near-accepted screens. Re-pair OSL Chats states to regions of one page. Move Cleanup into onboarding after Cover insertion. Remove Servers from review, not Discord Strip feature. Prove multi-profile/detection/Scrub/Strip behavior separately. | Per-screen status superseded by D56–D68. Home ownership changed again D58. |
D47 | Combined identity design: one page/two states, sanitized exact-match globally unique public profile, single-use 24h link, pre-mint warning, only last minted link active, all interactions real. | State B moved out of onboarding by D53. Public-name min/max/case conflicts with decision 11. Clipboard conflict resolved D49/D54. |
D48 | Delete recovery-protection refusal screen/gate/routes. Still request OS capture protection but always render recovery words; recovery-secret path remains distinct. | Supersedes D43’s “keep 003 state.” |
D49 | Clipboard ban applies to later app/sending, not user-initiated onboarding Copy. Friend invite app Copy stayed removed under this intermediate reading. | Superseded by D54, which makes consent—not location—the rule. |
D50 | Adopt new 006-007 and revised Send Mode design; no Manual/no screenshot-resistance switch. Authority becomes 72 pages. | 006/007 State B later moves under D53. |
D53 | Onboarding identity is State A only. No minted-link card/link generation in onboarding. Link minting lives in friends-add tab; carry 24h/single-use/latest-only behavior there. | D54 restores consensual Copy in friends tab. |
D54 | Clipboard rule is consent: user-pressed Copy of their expected value is allowed anywhere; autonomous read/write is banned. Restore invite Copy and ensure nothing copies without press. User-controlled Clipboard send mode remains. | Supersedes D31 absolute reading, D49 location split, D53 no-Copy consequence. |
D54(a) | Clipboard may be used only for tasks directly chosen by user. Test: point to control pressed and clipboard value matches expected copy; both required. | Sharpest current clipboard rule. |
D55 | Delete 003 design everywhere. Remove nine accepted screens from review and freeze with regression guard; near-accepted 001/016 remain until named defects fixed. Authority remains 72 pages. | Status later evolves. |
D56 | Six more screens accepted. Fix shared settings spacing once; fix remaining Home/Chats/Strip issues. Browser import/detection must answer behavior before visual review. | Review status later superseded D62/D67/D68. |
D57 | Ratified packs: Starter $2.99/5GB, Standard $5.99/50GB, Archive $11.99/150GB; no paid daily message cap; Free keeps its cap. Re-measure operation cost in real run before selling. Ship Window & Sounds and Security Settings sections with real existing-path wiring. Reconfirm QA shell exclusion. | Supersedes undecided price/ladder. |
D58 | Every claimed UI change requires before/after screenshots; audit multiple states/animations and actual clicks. Fix shared Settings/Chats causes, Home navigation, Strip tutorial. Home returns to team work due owner feedback. | Standing proof/process requirement. |
D59 | Account readiness records last 7 days, not one. Read/refresh proof/account-preconditions.json before asking owner. Existing Discord/Telegram/mail/provider pairs are present; remaining gaps are OSL Chats, second Instagram, isolated X. | D63 says generated evidence/attestation details. |
D60 | Do not route work through .codex-b until 19 Aug credit returns; use other agents. | Operational/time-bound, not product capability. |
D61 | Clause G must run from canonical and regenerate registry. 3,273 substantive tasks require observed red cases against packaged Windows artifact; exemptions explicit. Treat as a campaign. | Process/proof requirement. Does not itself prove any capability. |
D62 | Fifth review: five accepted; ten conditional on behavior; fix remaining Home/Cleanup/Appearance/Chats/Strip defects. Conditional appearance is not a pass. | Status later superseded D67/D68. Note text says “ten” but lists seven screens (018,019,025–029): internal count error. |
D63 | Account preconditions come from verifier plus dated owner attestation; attestation expires after 7 days. Store presence alone cannot prove signed-in. JSON is generated, never hand-edited; unverifiable stays UNKNOWN/UNMET. | Refines D59. |
D64 | Owner passes Scrub consent wording. | Initial caveat about two sentences missing is superseded by D64(a). |
D65 | Five undesigned routes ship: timed-delete-scheduler, settings/schedule, auto-whitelist-rules, friend, behaviour. Mark parity unavailable by ruling, not defect; behavioral proof still required. | Explicit D26/D27 parity exception. |
D66 | AI cover writer is proven only on Linux with real model/library. Windows artifact excludes it because llama-cpp-sys-2 cannot cross-compile; Windows AI writer remains absent/unproven and must be recorded that way. | Critical audit gap; never claim Windows coverage. |
D67 | Seven screens accepted and Settings set mostly done. Fix Detected Telegram logo, Cleanup slider behavior, Home icons/navigation/spacing, Chats comparisons. Browser import and Strip remain conditional on working to spec. | Later D68 accepts 018/019/031/043. |
D68 | Accept Browser import, Detected apps, Cleanup, Discord Strip after behavior work. Fix Home notification-bell action. Fix one shared left-offset/state-selection defect across six Chats screens and verify intended state before measuring. | Latest screen-review status in file. |
D64(a) | All four Scrub consent elements are present on rendered surface: control/real reading, service-rule risk, suspension risk, stopping; D64 caveat is void. | Latest Scrub consent interpretation. |
Supersession/conflict map that the audit must apply
1. Voice/beacons/custom roles: opening cuts/absence are obsolete. “Nothing left unbuilt,” enclave self-moderation, D2 and D16 make them shipping scope.
2. Sidebar: design rail is non-authoritative. Sidebar/Inbox/People/Privacy/Activity/Connections remain removed under 20(l), global sidebar ruling, D12(a), D41.
3. OSL Mail: R2 hard-cut language is superseded by D9(d): preserve as post-V1; do not gate V1 on it.
4. Central moderation: S5’s absolute language is refined, not discarded. Enclave self-governance and local AutoMod ship; OSL-central reporting/banning/content inspection remains forbidden.
5. VMs: “NO VM” is obsolete. Prefer local; Hyper-V OSL-QA-1 exists; Azure remains disabled; calibration VPSs remain forbidden.
6. Clipboard: T1 bounded automatic use and D31 absolute ban are obsolete formulations. Current rule is D54/D54(a): deliberate user-chosen Copy/use allowed; autonomous clipboard workspace/read/write banned.
7. Performance: D21 numbers are void. D44 is current, and four values are provisional until measured.
8. Relay expiry: D23’s open parked-object question is answered by D40/D44: delete uncollected relay object at relay expiry; view timer starts only on open.
9. Design/page count: D10’s original 71-page set changed under D39 and D50/D55; current authority count stated in file is 72 pages. Derive it; never hard-code.
10. 003 refusal: D43’s keep-state instruction is superseded by D48/D55: delete screen/gate/routes/design; keep only request for OS capture protection.
11. 006/007: combine into one onboarding identity-choice screen; D53 removes minted-link State B from onboarding and moves link behavior to friends-add tab; D54 allows a consensual Copy there.
12. Old Messages: D12(g) said Settings only, but D43 explicitly accepted screen 014 and says owner overrode that earlier ruling. Treat standalone screen as shipping unless a later ruling removes it.
13. AI cover: D66 is categorical. Linux library-level proof is not Windows proof; shipping Windows binary lacks feature.
14. Carrier E2E: no capability is end-to-end proven merely by function/unit/source evidence. Carrier visual fidelity requires real-account reference captures and runtime self-healing; D19 additionally requires the capability in one compiling/typechecking canonical tree.
Unresolved ambiguities/internal inconsistencies to call out
- Public-name rules conflict: decision 11 says case-preserving
[A-Za-z0-9_], max 16, min 1; D47 says lowercase, max 30, min 3. Both are in RULINGS.txt and D47 does not explicitly say it supersedes decision 11. Highest authority is internally inconsistent. - Decisions 20(b)–(i) are not self-contained. RULINGS says accepted but omits the actual clauses. Their requirements must be recovered from the referenced plan/decision source; otherwise SPECIFIED cannot honestly name their substance.
- Decision 17 is delegated but unresolved in this file. “Blocked wake-up connection — our judgement” names no chosen behavior.
- D15’s 30-day maximum is explicitly a delegated, overturnable choice while owner only confirmed the one-minute floor. Treat the floor as firm and upper bound as less direct.
- D20 binds X timer design but says X is contract-only/not promoted. Combine with opening conditional-carrier ruling; do not list X as shipping or proven unless its own proofs passed elsewhere.
- D42 uses A/B review labels without mapping them in RULINGS.txt. Requirements such as “B5 add them” are not auditable from this file alone and require the review artifact.
- D62 says ten conditionally accepted screens but enumerates seven. Use named IDs, not the count.
- Review acceptances prove owner visual judgment only unless explicitly conditioned on and accompanied by behavioral evidence. D62/D67 make that distinction; D68 explains why 018/031 were stronger, but code/evidence still must be audited independently.
High-value ruling-derived audit assertions
- Windows AI cover writing is not built into the shipping Windows binary by ruling D66; any Windows AI-cover PROVEN claim is false.
- A feature is not PROVEN until it is in canonical, the relevant Rust app and TypeScript typecheck, the real behavior is executed, its red case is observed against packaged Windows where required, and carrier overlays have real-carrier visual/self-heal proof where applicable (D19, D26/D27/D45(c), D58, D61, carrier-fidelity ruling).
- A checksum/package receipt can establish identity, never that the executable started/rendered/worked; no ruling authorizes treating checksum alone as runtime proof.
- Conditional visual “looks good” is not proof of behavior. D62 and D67 explicitly withhold pass until wiring works; D68 records only selected later conversions.
- Wordbank covers currently fail their ruling if a machine detects them above 50%; D37 says the recorded 99–100% recognition is a total failure, not a pass.
- Low Data Mode must visibly leave stored bytes at exactly zero during real send; ordinary offline sends refuse; zero allowance must not lock any local data.
- Group chat and enclave limits are different: 20 people versus no hard cap.
- All owner-review screenshot freshness and the exact running/accepted set must be established from current artifacts; the rulings are verdict history, not proof that today’s binary renders the accepted screen.